Data Recovery Case File · Logical Forensics · The Whodunnit

The case of the hollow files: vanished contents, intact folders, and a timestamp that named the culprit

This enquiry read like a detective's casefile, because its author had done detective work. A large desktop folder — 12GB, years of photos, documents and presentations — had lost every file while keeping every folder. Undelete software found the files easily, correct names and extensions intact — but every recovered copy was corrupt, unopenable, all of them. Every subfolder carried the same modified timestamp, to the minute. No ransom note, no renamed extensions, no malware findings from scans he'd already run, and — crucially — he'd restored nothing back to the drive. His conclusion: something mass-deleted or mass-corrupted everything simultaneously. The evidence deserved a proper trial.

SystemWindows laptop drive; affected scope: one large user folder (~12GB) and its subtree
Evidence suppliedAll files missing, all folders intact; undelete recovers correct names but universally corrupt contents; every subfolder modified at the identical minute; no notes, renames or detected malware; no writes made since discovery
VerdictCloud-sync placeholder eviction — the "files" were hollow stand-ins; the contents had been surrendered, not destroyed
Equipment usedWrite-blocked imaging · ACE Lab Data Extractor (filesystem forensics; signature carving) · cloud-side retrieval guidance

The suspects, examined

His own prime suspect — ransomware — deserved its interview first, and the evidence acquitted it on style: encryptors announce themselves (notes, renamed extensions, payment demands) because unannounced extortion collects nothing, and a wiper that silently destroys leaves damaged data, not this case's stranger artefact — files that undelete tools reconstruct perfectly by name yet which contain nothing openable. That artefact was the fingerprint that broke the case, because one culprit produces it exactly: a cloud-sync client evicting local content. The affected folder sat inside a cloud-synced location, and modern sync services can convert local files into placeholders — entries that keep their names, sizes-on-paper and positions while their actual contents are released from the disk, held "online-only." Triggered across a whole tree — by a storage-reclaim feature, a settings change, or a sync hiccup — it stamps every folder in the same administrative minute (his timestamp clue, decisive), leaves the tree structurally immaculate (his folders), and seeds the disk with hollow files that recovery software faithfully resurrects as hollow (his corrupt recoveries). On the image, the filesystem's own records confirmed it: the vanished entries bore the unmistakable anatomy of placeholders, not victims.

The recovery — from two places at once

A verdict of eviction transforms the job, because evicted content isn't destroyed — it's elsewhere, and partially still here. Elsewhere first: with the mechanism identified, the customer was walked through the cloud account's own recycle bin and version history, where the service's copies of the tree sat retrievable — the majority of the 12GB restored from the very system that had hollowed it locally. And here, for the remainder: on the write-blocked image, the original files' former clusters were carved by signature — photographs and documents whose full local bytes had been marked released but not yet overwritten, thanks entirely to his restore-nothing discipline — recovered intact and reconciled against the cloud set. The reunited folder was verified the only way that answers this case: by opening things, sampled across every file type that had turned to hollow shells.

Outcome

Effectively complete recovery, no criminal ever involved — and a modern moral this archive will need again: sync is not backup, and sync's helpful storage-saving features can look exactly like an attack. Know whether your important folders live in synced locations; know what "free up space" and "online-only" mean in your client; and if files ever vanish en masse with their folders intact, check the cloud service's own recycle bin before panicking — then stop writing to the disk, as this customer exemplarily did, so both recovery routes stay open. His forensics were right about everything except the perpetrator. The perpetrator was the help.

Mass file disappearance with folders intact

Check the identical-timestamp tell and whether the location is cloud-synced — then look in the service's web recycle bin and version history first; it's the fastest recovery route there is. Don't run undelete tools that write results back to the same drive, and treat "recovered but corrupt everywhere" as a clue, not a defeat — hollow placeholders resurrect hollow. And schedule a true backup of synced folders somewhere the sync client can't reach: the same convenience that evicted these files can, misconfigured, do worse.

Files vanished into thin air with the folders left standing?
Bring the evidence — call Bristol Data Recovery on 0117 332 1137 and we'll run the trial properly.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

Call us — 0117 332 1137
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →